Thursday, 25 April 2013

20 of the Sharpest LinkedIn Tips for Irresistible B2B Marketing

LinkedIn doesn’t have the same mass appeal as Twitter, or the billion members of Facebook, but that’s just fine.

Despite the fact that it took the network 6 years to reach 50 million members, experts estimate that someone new creates an account every two seconds in 2013. It remains one of the best destinations for B2B marketers, due to the fact it’s niche appeal. The average income of a LinkedIn member is around $109,000, which is consistent with its reputation as a hub for high-powered professionals and B2B decision makers.

There’s a lot to love about the network, and we’ve developed a comprehensive list of LinkedIn tips for your social media strategy.

1. Invest in Banner Images

Much like on Facebook, the first thing visitors to your LinkedIn company page will see is your banner image. Invest in a high-quality image that’s 646 x 220 pixels or larger, and consider using this space to promote your corporate culture, campaigns, or announcements.

2. Optimize Your Products & Services Tab

Fully optimize your company’s products and services page with visuals, and keyword-rich descriptions of what you have to offer.

3. Use Targeted Emails Thoughtfully

Companies can send followers of their business page email messages about updates, announcements, or new content offers. Be mindful of how often you contact your followers, and avoid spamming anyone.

4. Ask for Recommendations

Leverage your brand’s most-loyal promoters to lend credibility to your page with recommendations of your products and services.

5. Develop a Diverse Content Strategy

Your social media content strategy should include a balance of your best blog articles, offers, and industry-related news. Xactly Corporation, a winner of a LinkedIn Best Company page award in 2012, advises brands to “post content that interests your followers, and less about how great your company is.”

6. Reach out Often

While it’s wise to avoid filling anyone’s feed with senseless updates, stay top of mind to your fans by posting often. The life of a LinkedIn post may be longer than a Tweet, but The Walt Disney Company’s social media strategy team recommends at least one update daily.

7. Pay Attention to Insights

Much like Facebook, LinkedIn conveniently offers analytics and insights to brands. However, these insights include information on follower demographics, to help you ensure you’re reaching the right audience.

8. Search Before Posting

If you’re just joining a LinkedIn group and beginning to post, perform a search to ensure your question hasn’t already been answered by a group member.

9. Read the Rules

While many of the rules in the most-popular LinkedIn groups begin and end with “use common sense,” some have strict rules about how brand representatives can engage in self-promotion.

10. Listen

Some of the greatest value from LinkedIn groups may come from listening to the conversations among other professionals in your niche, or your target customers. You’ll be amazed at how much insight, and how many ideas for blog content you can mine from these talks.

11. Offer Assistance

If your social media strategy for LinkedIn groups begins and ends with posting links to your blog articles, you’ll win few fans or customers. Spend time in the group listening to conversations and offering help to other members where you can to build trust.

12. Connect With Content Advocates

Use LinkedIn groups as a resource for finding other motivated content creators in your niche. Comment on their contributions, share their work, and build relationships to gain exposure to a greater audience.

13. Join More Groups

LinkedIn members have the option of joining up to 40 groups. While few professionals have enough time to keep up on discussions in even 20 LinkedIn groups, join as many communities as you can offer value to.

14. Take Conversations Offline

In an ideal world, you’ll be faced with another group member who wants to learn more about what you have to offer. Take the conversation out of the public eye, and offer to provide more information via messages, phone, or email.

15. Know Whether it’s Right For You

While your budget for LinkedIn ads can be as low as $10 per day, Kissmetrics cautions that paid ads on the network aren’t right for everyone. Ensure your service or product has clear value for professionals and leaders.

16. Target Your Advertising

Take full advantage of LinkedIn’s options to target advertising to hit individuals with the same job description, industry, and geographic location as your buyer personas.

17. Use Images

Visual content is processed 60,000 times faster by the brain than text, so enhance your ads with images. LinkedIn research has found that female faces are the most effective visuals to use in paid ads on the network. Due to the small size of the display image, it’s wise to avoid complex graphics.

18. Write an Eye-Grabbing Headline

Your headline space is limited; so focus your text on solving a problem or creating an instant rapport with your target audience. The headlines picture below are both highly effective, because they’re targeted to specific groups – job seekers and MBA students.

19. Quantify Your Ad Copy

The sentence or two you have to describe your offer are essential. Use the space to convey the power and value of your offer; and quantify the benefit whenever possible, like “100k+ jobs.”

20. Direct Visitors to a Landing Page

Cost-per-click for LinkedIn paid ads can range from $2-5 per click, depending on a number of factors like audience targeted. Ensure every click counts by directing to a landing page on your website, where you can capture contact information.

Source: http://www.business2community.com/linkedin/20-of-the-sharpest-linkedin-tips-for-irresistible-b2b-marketing-0473821

Note:

Delta Ray is experienced web scraping consultant and writes articles on Yellow Pages Data Scraping, Screen Scraping Services, Linkedin Email Scraping, Amazon Product Scraping, Website Harvesting, IMDb Data Scraping, Yelp Review Scraping, Screen Scraping Services, Yelp Review Scraping and yellowpages data scraping.

Wednesday, 24 April 2013

LinkedIn buys Pulse for $90M as its publishing ambitions take shape

Stepping even further into the media fray, LinkedIn announced today that it has acquired the popular news reader app Pulse.
LinkedIn ended up paying $90 million for Pulse, 90 percent of which was stock and 10 percent cash. We heard last month that a deal between the two companies was possibly in the works, but at the time it seemed far from final.
The acquisition makes a lot of sense for LinkedIn, as it’s now focusing on becoming a major media destination, and not just a professional social network. We’ve noticed the power of LinkedIn’s news feed and LinkedIn Today, the company’s catered selection of interesting stories, in our own traffic records.
Pulse’s apps aggregate news updates from more than 750 publications, as well as social networks. So far the company has more than 30 million users. With the death of Google Reader (and seemingly, RSS in general), Pulse’s apps are now even more appealing to news hounds. (Yes, there’s an importer to easily bring your Google Reader feeds over to Pulse.)
“We believe LinkedIn can be the definitive professional publishing platform – where all professionals come to consume content and where publishers come to share their content,” said Deep Nishar, LinkedIn’s SVP of products, in a blog post today. “Millions of professionals are already starting their day on LinkedIn to glean the professional insights and knowledge they need to make them great at their jobs … Pulse is a perfect complement to this vision.”
In a brief Slideshare presentation explaining the acquisition, LinkedIn notes that it Pulse’s current apps “will continue to be support,” but the two companies are working on “new and innovative ways to publisher, discovery, and share your professional knowledge.”
Pulse co-founder Akshay Kothari confirmed that the companies apps won’t change in a blog post of his own: “LinkedIn is the perfect partner as we continue our journey. The company shares our passions and values, our belief in the power of knowledge and elevated discussion, particularly for professionals looking for insights to help make them better at what they do.”
The deal is sure to have pleased Pulse’s investors. The San Francisco-based company raised $10 million in funding from Redpoint Ventures, Mayfield Fund, and others.

Source: http://venturebeat.com/2013/04/11/linkedin-buys-pulse-newsreader-for-90m/

Note:

Delta Ray is experienced web scraping consultant and writes articles on Yellow Pages Data Scraping, Screen Scraping Services, Linkedin Email Scraping, Amazon Product Scraping, Website Harvesting, IMDb Data Scraping, Yelp Review Scraping, Screen Scraping Services, Yelp Review Scraping and yellowpages data scraping.

Tuesday, 23 April 2013

LinkedIn's hacky, wacky Wednesday

With twin security breaches – one of which was self-inflicted – LinkedIn suffered a brutal one-two punch to its reputation on Wednesday.

But analysts who watch the online privacy space caution to expect lapses like this to become more and more routine.

"This is just the latest data mismanagement fiasco," said Kris Tuttle, an analyst at Research 2.0. "To be honest, we get one of these breaches or another every other day. I think you're going to see this for a long time to come."

The social network site for professionals said it is looking into reports that a hacker posted 6.5m of its users' passwords online.

That news came just hours after two Israeli researchers revealed that LinkedIn is scraping user data from their calendars in mobile Apple devices, sending private information back to LinkedIn's servers.

"This will be a pervasive problem for the next 10 years. As long as there are human beings involved you're going to have a prevalence of these privacy and security breaches," said Tuttle.

"If they were an advisory client, I would say: 'You should make a CEO level commitment to spend the money on the best resources you can get and be the best practices leader in the area.' And they could. IBM is one phone call away and you're set."

Tuttle points out that as companies like LinkedIn or Facebook go through redesigns or overhauls, as they often do, privacy default settings often change without users realizing it.

But it's only going to get worse, he said, as everything from social networks to banks to any other service that trades in private information go through systemic upgrades.

"As companies are totally refreshing security infrastructure, it's going to remain a problem, this inconvenience of people having to change their data and update their passwords," he said.

"It's virtually impossible to pay attention to everything. One thing I would say is make sure you don't put too much of your privacy at risk."

A Russian forum user claimed Tuesday that he had hacked the professional social network, uploading 6,458,020 encrypted passwords (without usernames) as proof. That is a small fraction of LinkedIn's 150 million users, but still a significant breach.

LinkedIn encrypts its passwords using an algorithm called SHA-1, a hashing algorithm. ZDNet readers and several Twitter users have reported finding their passwords in the posted list of leaked info.

The company announced that it was "looking into reports of stolen passwords" on Wednesday morning, and experts advised users to change their passwords immediately.

Still, the news comes at an awkward time for LinkedIn. Just hours earlier, two researchers from Tel Aviv University revealed that the company's iOS app collects private information from calendar entries – including meeting notes – and sending them back to the company's servers without the knowledge of LinkedIn's customers.

"When it comes to social networks – particularly business social networks – trust is an important factor," said industry analyst Michael Gartenberg. "This morning you have two strikes against the company."

Calendar notes can often contain highly private information such as conference call login information, contact information of colleagues and even passwords.

"This is really hard to justify without explicit user permission. It's a major breach of trust," said Gartenberg. "It will be interesting to see how people react."

So far people are reacting with jokes.

LinkedIn does not have the sexy reputation of a younger-skewing social network like Facebook or Tumblr. Comedian Rob Delaney tweeted of the password leak Wednesday morning:

And finance journalist Felix Salmon slyly referred to the fact he is at a loss as to what his password was in the first place.

Others poked fun at the relentless reminder emails LinkedIn sends its users about unanswered invitations to connect.

But LinkedIn has been one of the more successful tech IPOs of the post-dotcom bubble era (or second bubble era, depending on your point of view). It has become a vital life insurance policy for people who find themselves looking for work, a good place to network, and an invaluable sales and human resources tool.

The company went public in May, trading at $93 a share. The shares hit an intraday low of $91.60 on Wednesday on the double blast of bad news.

"LinkedIn worked hard and established trust," said Gartenberg. "This is about a bad a one-two punch as it can get for a social network."

LinkedIn did not immediately return calls seeking comment.

The company posted a lengthy statement to its website Wednesday morning:

    For those not familiar with our calendar feature, with your permission, we sync with your mobile device's calendar to provide information about the people you are about to meet by showing you their LinkedIn profile.

    In order to provide our calendar service to those who choose to use it, we need to send information about your calendar events to our servers so we can match people with LinkedIn profiles. That information is sent securely over SSL and we never share or store your calendar information.

Not everyone was won over by LinkedIn's response.

"If that's the case – if you'd 'never use it' – why were you taking it? Why weren't you asking for permission," asked Gartenberg.

"If companies say 'We would never do anything with this information,' I always think there's an implicit 'today'. They won't use it now, but what happens when the company gets sold or something happens?"

Source: http://www.guardian.co.uk/technology/us-news-blog/2012/jun/06/linked-in-privacy-breach-hack

Note:

Delta Ray is experienced web scraping consultant and writes articles on Yellow Pages Data Scraping, Screen Scraping Services, Linkedin Email Scraping, Amazon Product Scraping, Website Harvesting, IMDb Data Scraping, Yelp Review Scraping, Screen Scraping Services, Yelp Review Scraping and yellowpages data scraping.

Online "data scraping" sparks debate about patient privacy

After a company collected information from a health website where intimate details of illnesses are shared, a question arises: How much confidentiality can users expect?

A recent "data scraping" incident involving a patient advocacy site ignited a discussion about the value of patient data and efforts to protect it.

Social networking health site PatientsLikeMe became aware in May that the Nielsen Co. was using its automated data collection tool, BuzzMetrics, to obtain data on its community members who often share intimate details of their illnesses, treatments and medication history online. Nielsen's automated system, which scrolls websites looking for specific keywords and topics, is used to monitor online "buzz" on services and products for clients, which include major drug manufacturers. Patients must create a unique login to participate in discussions on the PatientsLikeMe website, and Nielsen's system was creating member accounts to gain access to the discussion boards.

After The Wall Street Journal published an article about data scraping in which members of PatientsLikeMe were quoted as feeling violated after they discovered what Nielsen was doing, the company announced that it was no longer scraping sites for which a login is needed without the website operators' permission.

The incident prompted a larger discussion about two major themes: the importance of transparency and the importance and value of patient data -- such as what is contained on PatientsLikeMe -- to researchers who use it to develop new products, medicines and support tools for patients.

Patients felt their privacy had been violated, but for executives at PatientsLikeMe, the problem wasn't the practice of using deidentified data from the website. In fact, PatientsLikeMe has several partners to whom it sells deidentified data and is very open about that fact. The issue, the site claimed, was that Nielsen violated PatientsLikeMe's user agreement, which prohibits data scraping tools.

Ben Heywood, co-founder and president of PatientsLikeMe, said when a company like Nielsen takes data from a site such as his, there are no protections in place as there are between PatientsLikeMe and the vendors with whom it does business.

"Our patients know us as a company, they know our values, they put their trust in us that we will use the data responsibly and ethically, including choosing our partners," Heywood said. "They don't know that of any other random scraper, whether it's Nielsen or someone else."

Nielsen spokesman Matt Anchin said data scraping is high-level data collection that is not focused on individuals or groups. It is much more broad and is meant to analyze general attitudes toward particular products and services. Nielsen's automated systems scrape 130 million blogs, more than 8,000 message boards and forums and 40,000 usenet groups. It also scrapes Twitter and other social media sites.

Heywood hopes the recent developments and subsequent awareness it created about data use don't dissuade patients from using the sites and posting information. The incident gave him the opportunity to describe to members how the company tries to protect patients' privacy. For example, Nielsen's scraping activity was detected by a system PatientsLikeMe has in place to flag suspicious activity, including views of too many profiles or posts over a short period of time.
"Wake-up call"

Gilles Frydman, founder of the Assn. of Cancer Online Resources, said the incident at PatientsLikeMe was a "necessary wake-up call about how each of us must understand our complete loss of privacy." ACOR's privacy policy regarding how it maintains its mailing lists explicitly states that even though ACOR strives to deter abuse, "it is possible that unknown persons or entities could access and archive the lists without our permission."

Frydman discourages ACOR members from disclosing personal information they don't want to be made public on the mailing lists, but encourages the use of real names and information on the message boards.

"The conversations are of a much higher quality when people talk to real people," he said.

ACOR also has high-tech systems that help monitor and prevent data scraping. It does not sell patient data, however.

Tena Friery, a staff member at the Privacy Rights Clearinghouse in San Diego, said patients still can participate in online groups without disclosing identifiable information. She said it's important that patients read each site's privacy policies before participating.

Nielsen said that although it stopped scraping, without permission, sites that require a login, it is actively pursuing data acquisition arrangements with a number of those sites. It has established several relationships and will continue to do so, according to the statement.

Friery said patients always should assume that "information gathered for one purpose will ultimately be used for another."

Source: http://www.amednews.com/article/20101025/business/310259971/6/

Note:

Delta Ray is experienced web scraping consultant and writes articles on Yellow Pages Data Scraping, Screen Scraping Services, Linkedin Email Scraping, Amazon Product Scraping, Website Harvesting, IMDb Data Scraping, Yelp Review Scraping, Screen Scraping Services, Yelp Review Scraping and yellowpages data scraping.

Social Engineering – Scraping Data from Linkedin

Summary: A method and scripts to grab bulk data from Linkedin profiles and format it, using Burpsuite, curl, grep and cut. In this case to create a username list for identifying emails and domain accounts.

Foundation:
I was performing a relatively unique task for a social engineering engagement for a client. Normally I’ll just receive a list of email accounts and/or phone numbers of specific users the client wishes to test. In this case they didn’t want to provide ANY information at all. They wanted to see what I would be able to find and then target those users.

I started with the usual google searches looking for pertinent data and found a little. Used metagoofil and theHarvester as well, which turned up about 20 valid accounts. During my googling I found a very interesting portal page that allowed users to reset their domain passwords. I wasn’t interested in brute forcing any accounts (yet), but was able to use the functionality to test for valid accounts. I browsed to a webpage detailing some of the executives at the company and tried varying combinations of their names to find the format they used to create accounts. It turned out to be first initial last name, not surprisingly.

I then turned my attention to Linkedin and found over 1800 existing employees. If I could just grab all the names of employees and then format them I could then fire this list of usernames at the portal page to get a large list of valid user accounts. How best to do this?

Unfortunately Linkedin is one of the worst designed websites for automating this. If I were able to change the number of results per page I could simply do this manually and it wouldn’t take long. For example if I could return 100 results per page that would only be 18 pages to save manually and then grep out the profile names. That wouldn’t be so bad to save 18 pages manually. Unfortunately Linkedin has it hardcoded that you can only view 10 results per page. It looks like the limit might be 25 results for the Linkedin API, but the actual website appears to be limited to 10 per page. That means I’d have to browse to and save 180 pages manually, too much work. Thus trying to automate it with a script to crawl through each page, saving the output, looked like the best option.

To do this I used the intruder module of Burp Suite. I also needed a paid account for Linkedin, otherwise you would just see their first name and last initial. I borrowed an account (legitimately) from a friend and logged into Linkedin. This captured the request using the proxy intercept feature. I found the request for the search results page in history, right clicked and chose ‘send to intruder’.

On the positions tab for intruder you can see the HTTP request from the client. There are many variables as part of this GET request so the first step is to remove all of them with the ‘Clear §’ button. This removes all the variables that intruder will manipulate. Next select the page_num variable and select the ‘Add §’button.
Note that I changed the variable Keyword=ORG_NAME to protect the client, in reality it was just the organizations name. The attack type doesn’t necessarily matter for this test because we’re only manipulating a single variable, for the difference between the attack types check out the portswigger website.

Now select the payloads tab and choose numbers in the payload set dropdown. This section is pretty self explanatory. We want the page numbers to walk through every number from 1 to 180 and the step defines how much it increments each time. Once you’re ready click Intruder -> Start Attack.

Once the attack has completed you can highlight all the requests, right click and choose ‘save selected items’. Choose a folder and all the contents of the requests will be saved in one file. This works perfectly for what we’re trying to do as we can simply grep out the first and last name.

There were a few locations in the html file that had the persons first and last name. The one that seemed like it would be the easiest to manipulate were part of a link that looked like this
<a href="http://www.linkedin.com/people/invite?from=profile&key=2540332&firstName=Tyler&lastName=Wrightson&amp&#8230;

So to grab all the names I grepped for that page with the command;

grep "people\/invite" burpsuite.txt | cut -d";" -f3,4 >> names.txt

Then I put them in a nice format using search and replace in vi
vi
%s/firstName=//g
%s/&lastName=/ /g
%s/&amp//g

I also noticed that some usernames had plus and percent sign symbols for additional information like using a nickname in quotes for their title. Because there were only a few I went through and manually removed them to make sure that it didn’t interfere with their last name.

Now we have a perfectly constructed list of first name and last name separated by a space.

#grab first initials with
cat names.txt | cut -c1 >> first_initial.txt
#grab last names with
cat names.txt | cut -d " " -f2 >> last_names.txt

Because there was an even amount of items I simply pasted each of these files manually into an excel spreadsheet, saved the spreadsheet as a csv and then I could manipulate them as needed. In this case I simply did a search and replace on the comma to replace with nothing and voila, 485 account names to test in a perfect newline delimited file.

Next I created a perl script to use each name in the file to construct a large post data file to be used by curl. The name of the file was $USERNAME.post
I then used curl to hit the password page with each of the usernames like so
curl --data $_.post https://client.com/reset_password.aspx >> $_.response\n";

*Note that this is also not the actual name of the client’s password reset page.

This took the data in the USERNAME.post file, sent the request to the password reset page and saved the output as USERNAME.response. Thus I could then grep for a string that indicated a correct login in all of the .response files and grep would give me the name of the user that was valid as part of the file name. I did this in part because the username was not spit back at the user in the html of the page.

When this was all complete I had 110 valid domain usernames! Not bad for a start. I then wanted to remove those legitimate names from the larger list so that I could target the valid credentials differently than the potentially valid account names. I did this with the following command

#remove duplicate entries between two files with
comm -3 full_list.txt valid_accounts.txt >> possible_names.txt

Source: http://twrightson.wordpress.com/2012/08/05/social-engineering-scraping-data-from-linkedin/

Note:

Delta Ray is experienced web scraping consultant and writes articles on Yellow Pages Data Scraping, Screen Scraping Services, Linkedin Email Scraping, Amazon Product Scraping, Website Harvesting, IMDb Data Scraping, Yelp Review Scraping, Screen Scraping Services, Yelp Review Scraping and yellowpages data scraping.